tasks
Remove persistent self-update receipt
Keep Forma install-script deployments single-file at rest while retaining verified, recoverable explicit self-update transactions.
Goal
Keep official install-script deployments single-file at rest without weakening exact-release verification, explicit update approval, or recoverable executable replacement.
Sources
In Scope
- Stop creating or depending on the adjacent
forma.install.jsonreceipt. - Treat explicit self-update invocation and confirmation as authority to replace the running executable.
- Keep recovery metadata transient and remove it after successful update or rollback.
- Leave existing receipt files untouched.
- Align install scripts, CLI output, tests, and active documentation.
Out of Scope
- Inferring an installation manager from executable paths.
- Automatically invoking mise, WinGet, or editor package management.
- Removing receipt files created by Forma v0.1.29.
- Passive update notifications or background updates.
Acceptance Criteria
- A fresh official-script installation leaves only the Forma executable in the install directory.
- Reinstalling over a directory containing
forma.install.jsonleaves that file unchanged. - An explicitly confirmed self-update can replace any supported standalone Forma executable.
- Transaction journal, staging, backup, and lock files exist only while needed for update or recovery.
- The complete repository gate and configured workspace health pass.
Implementation Evidence
Implemented locally on 2026-07-30 for inclusion in the next coordinated Forma release:
- the Unix and Windows installers validate the installed binary without creating, reading, overwriting, or deleting a receipt;
- self-update uses the compiled official repository identity and the running binary version;
- explicit invocation and confirmation replace persistent installation ownership;
.forma-update.jsonrecords only an active or interrupted update transaction and is removed with staging, backup, and lock artifacts after reconciliation;- the successful self-update JSON contract advances to schema version 2 and removes
installationOwner; - a live exact-release
--reinstall --check --jsonwithout a receipt reportscanApply: true; - focused CLI and cross-platform installer tests pass;
mise run checkpasses.
The installer change and the first receipt-free CLI release should be published as one coordinated release. Forma v0.1.29 still requires its receipt to apply an update, so this source change should not be pushed to main as an isolated installer-only delivery.
Release Evidence
Released in releases/forma-v0.1.30 on 2026-08-05 from candidate 0cf545f42b0432c3a804bc17d2c8530702f64f4d.
- Exact-source local and main gates passed the Unix and Windows installer regressions and all five platform self-update contracts.
- Fresh official-script installation remained single-file at rest, while an existing legacy receipt remained byte-for-byte unchanged and inert.
- The
v0.1.29tov0.1.30transition completed without persistent transaction, staging, backup, or lock artifacts. - The published 22-asset Release and independent managed-install verification passed for
forma 0.1.30.